From Aug–Oct 2025, GreyNoise observed a surge in exploitation attempts against PHP and PHP-based frameworks as attackers deployed cryptominers—driven by rising Bitcoin prices and higher mining payoffs.
A vulnerability was found in GNU C Library. It has been declared as problematic. The affected element is an unknown function. Such manipulation leads to improper resource management.
This vulnerability is listed as CVE-2010-4756. The attack may be performed from remote. There is no available exploit.
A vulnerability classified as problematic was found in yaml-cpp 0.5.3. This issue affects the function SingleDocParser::HandleNode of the component YAML File Handler. The manipulation results in memory corruption.
This vulnerability is identified as CVE-2017-5950. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in yaml-cpp 0.6.2. Affected by this vulnerability is the function Scanner::EnsureTokensInQueue. Performing manipulation results in memory corruption.
This vulnerability is known as CVE-2018-20573. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability, which was classified as problematic, was found in yaml-cpp 0.6.2. Affected by this issue is the function SingleDocParser::HandleFlowMap of the component YAML File Handler. Executing manipulation can lead to memory corruption.
This vulnerability is handled as CVE-2018-20574. The attack can be executed remotely. There is not any exploit available.
A vulnerability labeled as problematic has been found in yaml-cpp 0.6.2. This impacts the function SingleDocParser::HandleFlowSequence of the component YAML File Handler. Executing manipulation can lead to memory corruption.
This vulnerability is registered as CVE-2019-6285. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in IBM Data Risk Manager up to 2.0.6. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation results in use of hard-coded password.
This vulnerability is reported as CVE-2020-4429. The attack can be launched remotely. No exploit exists.
A vulnerability labeled as critical has been found in python-py up to 1.9.0. Affected by this vulnerability is an unknown functionality. The manipulation results in incorrect regular expression.
This vulnerability is cataloged as CVE-2020-29651. The attack must originate from the local network. There is no exploit available.
It is advisable to implement a patch to correct this issue.
A vulnerability described as critical has been identified in Oracle FLEXCUBE Universal Banking up to 14.4.0. This vulnerability affects unknown code of the component Apache Batik. Such manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2020-11987. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in Oracle Enterprise Repository 11.1.1.7.0. It has been rated as critical. Affected is an unknown function of the component Apache Batik. The manipulation leads to improper input validation.
This vulnerability is listed as CVE-2020-11987. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in Oracle Fusion Middleware MapViewer 12.2.1.4.0. Affected by this vulnerability is an unknown functionality of the component Apache Batik. The manipulation results in improper input validation.
This vulnerability is cataloged as CVE-2020-11987. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in DMitry 1.3a. This impacts the function nic_format_buff of the component Whois Handler. The manipulation as part of Response leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2020-14931. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in Dassault Systèmes DELMIA Apriso up to 2025. It has been rated as critical. This affects an unknown part. This manipulation causes code injection.
This vulnerability is handled as CVE-2025-6204. The attack can be initiated remotely. Additionally, an exploit exists.
This issue seems to be a false positive. Please check the referenced sources and consider omitting this entry entirely. The issue could not be reproduced from a GNU Bison 3.8.2 tarball run in a Fedora 42 container.
Further analysis revealed that this issues is a false-positive. Please take a look at the sources mentioned and consider not using this entry at all. The issue could not be reproduced from a GNU Bison 3.8.2 tarball run in a Fedora 42 container.